{
 "jurisdiction_id": "BE",
 "jurisdiction": "Belgium",
 "url": "https://dataprotection.gi/jurisdictions/belgium/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 37,
  "sub_modules": 57,
  "source_register": 21
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/belgium/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Full GDPR-aligned statutory framework in force with an operational, active supervisory authority; only narrow public-sector carve-outs from administrative fines.",
   "claims": [
    {
     "statement": "The Belgian Data Protection Authority (APD-GBA), based in Brussels, is the national supervisory authority responsible for GDPR enforcement in Belgium.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/about-edpb/our-members_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Belgium implemented the GDPR through the Act of 30 July 2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data, together with the Act of 3 December 2017 Establishing the Data Protection Authority.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/belgium?article_type=insight",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Belgian Data Protection Act applies to both private and public controllers and processors, except that public authorities (other than public-law legal persons offering goods or services on a market) are excluded from GDPR Article 83 administrative fines.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/belgium-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Belgian Data Protection Act applies to processing carried out in the context of the activities of an establishment of a controller or processor on Belgian territory, regardless of whether the processing itself takes place in Belgium.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/belgium-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Controllers and processors appointing a DPO under GDPR Article 37 must publish the DPO's contact details and communicate them to the Belgian DPA, constituting the principal filing obligation under the Belgian regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/belgium?article_type=insight",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/belgium/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core lawful-basis and special-category rules are GDPR-aligned and actively enforced by the Belgian DPA; pseudonymisation/anonymisation guidance is thin.",
   "claims": [
    {
     "statement": "Employees' personal data may be processed on the Article 6(1)(c) GDPR Member State legal-basis route where necessary for establishing, implementing, or terminating an employment relationship, including under a collective bargaining agreement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/belgium-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Belgian DPA's direct marketing guidelines require that consent be free, specific, informed, and unambiguous, and state that 'consent or pay' models are generally invalid.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/belgium-belgian-dpa-publishes-updated-direct-marketing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Belgian DPA fined a company €45,000 after finding it processed employees' fingerprints (special-category biometric data) for time-registration without articulating a valid Article 9 legal basis and in breach of purpose-limitation and minimisation principles.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/news/belgium-belgian-dpa-fines-company-45000-gdpr-violations",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/belgium/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights framework is GDPR-aligned and enforced through repeated Belgian DPA decisions; portability enforcement activity specifically is thin.",
   "claims": [
    {
     "statement": "Where a controller does not act on a data subject's rights request, it must inform the data subject without delay and at the latest within one month of receipt, of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority or seeking a judicial remedy.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02016R0679-20160504",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Belgian DPA fined a controller €1,000 for not responding to a data subject's request to object to processing of his data for marketing purposes and for failing to cooperate with the authority's injunction.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / Belgian DPA",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/belgian-dpa-imposes-fine-1000-euro-controller-not-responding-request-object_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In Decision No. 86/2026, the Belgian DPA fined an employer €8,500 after it kept a former employee's professional mailbox active and failed to respond to the employee's erasure request.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/belgium-apd-fines-ynv-eu8500-unlawful-processing",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/belgium/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "All core controller/processor duties are GDPR-aligned, actively guided by Belgian DPA published lists, and enforced through repeated fines; joint-controller arrangements lack Belgium-specific findings.",
   "claims": [
    {
     "statement": "The Belgian DPA maintains a published list of processing operations requiring a DPIA, including biometric data collected to uniquely identify data subjects in a public space or a private but publicly accessible area.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/belgium-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Controllers and processors meeting the GDPR Article 37 designation criteria must appoint a DPO, publish the DPO's contact details, and communicate those details to the Belgian DPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/belgium?article_type=insight",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Belgian DPA found a company in breach of Article 30(1)(a)-(d) GDPR for failing to maintain adequate records of processing activities relating to biometric time-registration data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/news/belgium-belgian-dpa-fines-company-45000-gdpr-violations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In the case of a personal data breach, controllers must notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02016R0679-20160504",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Belgian DPA fined a controller €1,500 for unlawful processing via a video-surveillance system, finding that camera positioning also infringed the data-protection-by-design principle.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / Belgian DPA",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/belgian-dpa-fine-unlawful-processing-video-images_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Belgian DPA ordered Freedelity to ensure personal data retention does not exceed three years, having found its prior retention period excessive and in breach of the storage-limitation principle.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/belgium-belgian-dpa-orders-eu5000-daily-fine-and",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/belgium/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer mechanisms are fully operative and actively used (BCR lead-authority role, Schrems II guidance); adequacy grant/receipt is not a Member-State-level competence.",
   "claims": [
    {
     "statement": "Under GDPR Chapter V as applied in Belgium, transfers to third countries may take place on the basis of a European Commission adequacy decision or, absent one, on appropriate safeguards providing enforceable rights and effective legal remedies for data subjects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sme-data-protection-guide/international-data-transfers_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Belgian DPA, acting as lead supervisory authority, has submitted draft Binding Corporate Rules decisions for EDPB Article 64 opinion, including for Oregon Tool, Inc. (formerly Blount).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/our-work-tools/our-documents/member-state/belgium_en?page=3",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Following the Schrems II judgment, the Belgian DPA published a statement on 31 August 2020 noting consequences for controllers and processors transferring personal data to third countries.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/europe-data-protection-authorities-react-schrems-ii-judgment-updated-12-august-2020",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/belgium/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Strong, sourced coverage of telecoms and employment overlays; other sectors carry an evidentiary gap requiring escalation.",
   "claims": [
    {
     "statement": "The Belgian DPA fined water utility SWDE €86,000 (Decision No. 102/2026) for violations of the GDPR and the Belgian Electronic Communications Act (LCE) relating to systematic call recording without valid consent and inadequate transparency to callers and employees.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/belgium-belgian-dpa-fines-swde-eur86000-gdpr",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Belgian employers' access to employees' professional e-communications is governed by Collective Bargaining Agreement (CBA) No. 81, which the Belgian DPA has interpreted as requiring compliance with finality, transparency, and proportionality principles rather than reliance on individual employee consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/2012-09-01-belgium-belgian-dpa-clarifies-policy-on-workplace-cyber-surv",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "green",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/belgium/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Strong enforcement record across cookies, dark patterns, cross-context advertising (TCF) and direct marketing; opt-out-signal and clean-room specifics are thin.",
   "claims": [
    {
     "statement": "The EDPB required the Belgian DPA, acting as lead supervisory authority, to reconsider on the merits a NOYB complaint against Belgian public broadcaster VRT concerning cookie banners, after the Austrian DPA objected to the Belgian DPA's proposal to dismiss the complaint on procedural grounds.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/edpb-requires-belgian-dpa-to-handle-the-merits-of-noyb-cookie-banner-complaint_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Belgian DPA's Litigation Chamber fined IAB Europe €250,000 after finding its Transparency and Consent Framework (TCF) could lead to loss of control over personal information for large groups of citizens, and ordered deletion of personal data already processed within the TCF system.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/belgian-dpa-fines-iab-europe-250k-euros-over-consent-framework-gdpr-violations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Belgian DPA imposed corrective measures and a daily fine of €5,000 (capped at €100,000) on Freedelity for non-compliant consent mechanisms and excessive data collection via loyalty-card identity-document scanning.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/belgium-belgian-dpa-orders-eu5000-daily-fine-and",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Belgian DPA's updated Recommendation No. 1/2025 on direct marketing states that consent and legitimate interest are the primary lawful bases, requires consent to be free, specific, informed and unambiguous, and requires parental consent for marketing directed at children under 13.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/belgium-belgian-dpa-publishes-updated-direct-marketing",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/belgium/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Strong sourced coverage on biometric DPIA triggers and state-surveillance carve-outs; profiling/ADM-transparency and genetic-data specifics were not substantiated, and AI risk-assessment rules remain proposals.",
   "claims": [
    {
     "statement": "The Belgian DPA's mandatory DPIA list requires a DPIA for biometric data collected to uniquely identify individuals present in a public space or a privately-owned but publicly accessible area.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/belgium-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Title 3 of the Belgian Data Protection Act specifically addresses processing of personal data by intelligence and security services, the armed forces, classification and security-clearance processes, the Coordination Unit for Threat Analysis, and passenger-data processing, establishing derogations from the general GDPR regime for these activities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/belgium-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 20 January 2026, the EDPB and EDPS adopted a Joint Opinion on the 'Digital Omnibus on AI', at the European Commission's request, addressing interfaces between the GDPR and AI-related risk-assessment obligations relevant to Member States including Belgium; this remains a legislative proposal, not yet adopted law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "EDPB/EDPS",
     "source_url": "https://www.edpb.europa.eu/news/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while-raising-key_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/belgium/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Strong sourced coverage of the age-13 threshold and parental-consent rule; education-settings and dependent-adults sub-modules carry an evidentiary gap.",
   "claims": [
    {
     "statement": "The Belgian Data Protection Act sets the age of consent for children's data processing at 13 years, below which parental consent is required, derogating from the GDPR default age of 16.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/belgium?article_type=insight",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Belgian DPA's direct marketing guidelines require that information addressed to children be adapted to the child's age and that parental consent be obtained for marketing to children under 13.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/belgium-belgian-dpa-publishes-updated-direct-marketing",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/belgium/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Robust, judicially-tested enforcement powers with continuous 2026 enforcement activity; capacity/independence concerns are a noted but non-disqualifying risk factor.",
   "claims": [
    {
     "statement": "Infringements of basic GDPR principles, including Articles 5 and 6, can be subject to administrative fines of up to €20,000,000 or up to 4% of total worldwide annual turnover, imposed by the Belgian DPA's Litigation Chamber and subject to appeal before the Market Court, part of the Brussels Court of Appeal.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/brussels-court-of-appeal-overrules-first-dpa-fine-to-a-private-company",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Belgian Data Protection Act grants both data subjects and the Belgian DPA the right to obtain a cease-and-desist order, enforceable under forfeiture of a penalty, against infringing controllers, and permits class-action-type proceedings.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/belgium-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A data subject may lodge a complaint with a supervisory authority or seek a judicial remedy directly before the competent courts where a controller fails to act on a rights request.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02016R0679-20160504",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Between April and May 2026 the Belgian DPA issued multiple enforcement decisions, including an €8,500 fine against Y.NV (Decision 86/2026) for unlawful email retention and an €86,000 fine against SWDE (Decision 102/2026) for unlawful call recording, reflecting continued active enforcement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/belgium-apd-fines-ynv-eu8500-unlawful-processing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB publicly expressed concern that proposed Belgian legislative reforms would strengthen parliamentary oversight over the Belgian DPA, raising independence concerns relevant to the regulator's institutional capacity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/edpb-expresses-concern-about-proposed-reforms-for-belgian-dpa/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 11 February 2026, the EDPB and EDPS adopted a Joint Opinion raising concerns that the proposed Digital Omnibus Regulation could narrow the GDPR definition of personal data and increase the risk-notification threshold and deadline for data breaches; this remains a legislative proposal, not yet adopted law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "EDPB/EDPS",
     "source_url": "https://www.edpb.europa.eu/news/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while-raising-key_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}